I have a weird issue of getting alert after 4 hours of the event. Logs in the device sending syslog has correct time. When i query in sumo, i see the event happened for example at 2 pm while the event actually happened at 10 AM in the morning which is 4 hours earlier. However, if i check r"use receipt time" in sumo query dashboard, i do see the logs at actual time. So, how do i generate alert with checked "use receipt time"?
Please sign in to leave a comment.